Skip to main content

UniFi Cloud | UniFi Fabric Sites Not Discovered

Overview ✨

When deploying the UniFi Cloud Inspector in Liongard, the parent inspector automatically discovers and provisions child inspectors for your managed UniFi sites via the Ubiquiti Site Manager API.

However, if your network environment uses UniFi Fabric (Site Magic / SD-WAN Mesh) across consoles, those Fabric member sites may not automatically appear under Discovered Systems, even though standalone sites are discovered normally.

This article explains why this occurs and provides step-by-step instructions to configure multi-fabric visibility in Liongard.

⚠️ Known limitation: UniFi Cloud child discovery may not currently include sites configured as members of a UniFi Fabric, also known as Site Magic or an SD-WAN mesh. This page describes the observed behavior, impact, troubleshooting steps, and available workarounds.


Symptoms and Cause

  • The UniFi Cloud Parent Inspector completes its inspection run successfully with no errors.

  • Standalone UniFi sites are discovered and listed under Discovered Systems.

  • Sites configured as members of a UniFi Fabric (Site Magic) are missing from Discovered Systems and do not emit child inspectors.

Why this can happen?

Ubiquiti’s Site Manager API (/v1/sites, /v1/hosts, /v1/devices) scopes returned resources strictly to the Ubiquiti account that created the API key.

  • In many UniFi Fabric architectures, member consoles are owned or managed under different accounts or organization boundaries.

  • While the Ubiquiti Site Manager web portal displays all Fabric members to users with delegated portal access, Ubiquiti’s Site Manager API does not return consoles/sites owned outside that specific API key’s account.

  • Because Liongard provisions child inspectors directly from Ubiquiti’s API payload, any site not returned by the API cannot be auto-discovered.

  • Currently, Ubiquiti does not support a single, cross-tenant API key that spans multiple distinct Fabrics.


Steps to Resolve

‼️ Prerequisites - Important: Console Owner Account Required

The Ubiquiti Site Manager API key must be generated by the account that owns the console(s).
​

API keys generated by invited administrators will result in 403 Forbidden: user is not the owner of this host errors when child inspectors attempt to collect data.

  • Administrative / Owner access to the Ubiquiti account(s) managing the Fabric consoles.

  • Liongard Administrator permissions to add new Parent Launchpoints.

Step 1: Identify the Console Owner

  • Determine which UniFi account has Owner permissions for the consoles participating in the UniFi Fabric.

Step 2: Generate a Site Manager API Key

  1. Sign in to the [Ubiquiti Site Manager Portal] (https://unifi.ui.com) using the Console Owner account for the Fabric.

  2. Navigate to Settings → API Keys.

  3. Click Create API Key, give it a descriptive name (e.g., Liongard Fabric - <Fabric/Client Name>), and save the generated key.

Step 3: (Optional) Validate the API Key via CLI

Before configuring Liongard, verify that Ubiquiti’s API returns the expected Fabric sites:

curl "https://api.ui.com/v1/sites?pageSize=200" -H "X-API-Key: <YOUR_API_KEY>"

Confirm that the JSON response contains the member sites and console host records.

🔒 Security Notice: Never paste active API keys into tickets, emails, or public chat channels.

Step 4: Add a Dedicated UniFi Cloud Parent Launchpoint in Liongard

  1. In Liongard, navigate to Admin → Inspectors → Unifi Cloud (or go to your target Environment).

  2. Click Add System

  3. Name the launchpoint descriptively (e.g., UniFi Cloud - <Fabric Name>).

  4. Enter the Site Manager API Key generated in Step 2.

  5. Save the launchpoint and click Run to execute the inspection.

ℹ️ For detailed instructions, please refer to the following guide : Unifi Cloud Inspector Setup Guide

Step 5: Repeat for Additional Fabrics (One Key per Fabric)

Because Ubiquiti API scopes are bound per owner/Fabric:

  • Generate a separate Site Manager API key for each distinct UniFi Fabric.

  • Add a dedicated UniFi Cloud Parent Launchpoint in Liongard for each key.

Step 6: Review & Activate Discovered Systems

  1. After the parent inspector run completes, navigate to Discovered Systems tab.

  2. Locate the newly discovered child inspector sites belonging to the Fabric.

  3. Review and Activate the child inspectors (or assign them to their respective Liongard environments).


Best Practices & Good to Know

Topic

Detail

No Duplicate Systems

Each parent launchpoint processes its own discovered entities independently. Adding a second parent launchpoint for a Fabric will not duplicate existing standalone sites.

Existing Launchpoints

Standalone sites can remain mapped to your existing primary UniFi Cloud parent launchpoint. You only need dedicated parent launchpoints for separate Fabric scopes.

Direct Inspector Alternative

If a Fabric console cannot use the Site Manager Cloud API, deploy an on-premises or cloud-accessible Liongard Agent and configure an individual UniFi Network inspector directly targeting the local console address (HOST_URL + console NETWORK_API_KEY from Settings → Control Plane → Integrations).


When to Contact Liongard Support 🦁

Contact Liongard Support if you’ve followed the steps in this article and UniFi Fabric (Site Magic) sites are still not discoverable, or if you’re unsure whether it’s safe to activate a discovered child inspector.

ℹ️ Partner guidance: If the discovered-child list does not clearly identify the target site or environment, do not activate the child based only on an opaque identifier. Confirm the mapping before activation to avoid assigning data to the wrong customer environment. Use the following guide as reference : Unifi Cloud | Troubleshooting Unrecognized Discovered Systems

Reach out to Support when:

  • Fabric sites are visible in the UniFi Portal but missing via API

    • You can see the sites in the UniFi Site Manager portal, but the API response does not include them.

    • Example validation:

curl "https://api.ui.com/v1/sites?pageSize=200&__atl_rovo=disable_public_resolution" -H "X-API-Key: <redacted>"
  • If the sites don’t appear in the API response, Liongard cannot discover them from that key.

  • You’re unsure which UniFi account owns the Fabric consoles

    • The Site Manager API key generally needs to be created by the console owner account. If the wrong owner/account is used, discovery may be incomplete or child inspections may fail.

  • Child inspectors are discovered but fail to inspect

    • You see children appear, but inspection results fail (commonly due to API scope/ownership restrictions).

  • You have multiple Fabrics and aren’t sure how many launchpoints you need

    • In all cases it’s one API key + one UniFi Cloud parent launchpoint per Fabric (or per owner scope).

  • You need help proving site-to-environment mapping

What to include in your Support request

To help Support troubleshoot quickly, include:

  • The UniFi Cloud parent launchpoint name

  • A screenshot of:

    • Discovered Systems (showing missing Fabric sites or ambiguous child entries)

    • The relevant UniFi Site Manager portal view showing the Fabric sites

  • Output (redacted) from the API validation call above:

    • Do not paste the full API key

    • It’s OK to share whether the Fabric sites appear, and (optionally) a redacted snippet showing site names/IDs

  • The approximate time of last inspection run and any visible error message(s)

‼️ Security note: Never paste Site Manager API keys, Network API keys, or console credentials into tickets, screenshots, or chat. Redact secrets before sharing diagnostics.


Related Reference Articles

🚨 Note : We may occasionally provide links to third-party tools or resources for additional reference. These resources are offered for convenience only, and Liongard does not control, maintain, or guarantee their functionality, accuracy, or availability. Please review and use any third-party resources at your own discretion.

Did this answer your question?